Vulnerability CVE-2010-4302


Published: 2010-11-22   Modified: 2012-02-13

Description:
/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it easier for local users to obtain sensitive information by recovering the cleartext values, aka Bug ID CSCti54010.

See advisories in our WLB2 database:
Topic
Author
Date
High
Cisco Unified Videoconferencing multiple vulnerabilities
Florent Daignier...
24.11.2010

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
Cisco -> Unified videoconferencing system 5110 firmware 
Cisco -> Unified videoconferencing system 5115 firmware 
Cisco -> Unified videoconferencing system 5110 
Cisco -> Unified videoconferencing system 5115 

 References:
http://www.trustmatta.com/advisories/MATTA-2010-001.txt
http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html
http://seclists.org/fulldisclosure/2010/Nov/167

Copyright 2024, cxsecurity.com

 

Back to Top